SOTERIA HEALTHCARE TECHNOLOGIES LLC
SOTERIA BIOMETRIC DATA RETENTION AND DESTRUCTION POLICY
Soteria Credentialing LLC ("Soteria") maintains this Biometric Data Retention and Destruction Policy to govern the collection, retention, and destruction of biometric identifiers and biometric information.
Biometric Data Covered
This Policy applies to biometric identifiers and biometric information, including facial recognition templates and palm vein templates collected through Soteria's systems.
Purpose
Biometric information is collected solely for identity verification, credentialing, access control, and fraud prevention.
Retention Schedule
Soteria retains biometric information only while an active customer subscription exists and the information is necessary to provide services.
Upon subscription cancellation, expiration, or termination, Soteria permanently deletes associated biometric records without unreasonable delay.
Destruction Methods
Biometric records are securely deleted from production systems and backups in accordance with Soteria's information security procedures.
Prohibited Uses
Soteria does not sell, lease, trade, or otherwise profit from biometric information.
Security Controls
Soteria maintains reasonable safeguards to protect biometric information, including encryption in transit and at rest, access controls, monitoring, and audit logging.
Policy Updates
Soteria may revise this Policy periodically to comply with applicable law and evolving security standards.
